Even with OT network visibility, critical infrastructure operators struggle with legacy equipment
Large critical infrastructure operators run seven separate security tools on average, and most still cannot see every asset on their operational technology (OT) networks. That …
Automation, AI agents or people? Sorting out who handles each security finding
Just over half of the 200 senior security and technology leaders polled for ArmorCode say their organizations will struggle to simplify their software security programs if …
How RMM abuse gives attackers a way in that looks like business as usual
Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. …
AI is giving attackers a head start, Microsoft warns
Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 …
Criminal recruiters want people on your payroll
Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information …
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in …
AI agents keep access to company data after their work is done
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a …
Many expect AI in the SOC to make entry jobs harder to get
A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar …
Employment scam victims tripled at financial firms in 21 countries
Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries. The 258% rise outran …
Most open critical and high flaws are over 90 days old
Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems …
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the …
Deepfakes become a board priority once an executive falls for one
Nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year, while just 10% say their organizations have purpose-built defenses, …
Featured news
Resources
Don't miss
- Automation, AI agents or people? Sorting out who handles each security finding
- Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)
- Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)
- Data breach at Denmark’s population register exposes 8.8 million people
- U.S. Bank CISO says the security role keeps growing and no one can own all of it